Lucene search

K
cveRedhatCVE-2015-3187
HistoryAug 12, 2015 - 2:59 p.m.

CVE-2015-3187

2015-08-1214:59:12
CWE-200
redhat
web.nvd.nist.gov
68
cve-2015-3187
apache subversion
path-based authorization
sensitive path information
nvd

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

AI Score

7.3

Confidence

High

EPSS

0.001

Percentile

46.5%

The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8.14, when path-based authorization is used, allows remote authenticated users to obtain sensitive path information by reading the history of a node that has been moved from a hidden path.

Affected configurations

Nvd
Node
apachesubversionRange1.7.20
OR
apachesubversionMatch1.8.1
OR
apachesubversionMatch1.8.2
OR
apachesubversionMatch1.8.3
OR
apachesubversionMatch1.8.4
OR
apachesubversionMatch1.8.5
OR
apachesubversionMatch1.8.6
OR
apachesubversionMatch1.8.7
OR
apachesubversionMatch1.8.8
OR
apachesubversionMatch1.8.9
OR
apachesubversionMatch1.8.10
OR
apachesubversionMatch1.8.11
OR
apachesubversionMatch1.8.13
Node
applexcodeRange7.2.1
VendorProductVersionCPE
apachesubversion*cpe:2.3:a:apache:subversion:*:*:*:*:*:*:*:*
apachesubversion1.8.1cpe:2.3:a:apache:subversion:1.8.1:*:*:*:*:*:*:*
apachesubversion1.8.2cpe:2.3:a:apache:subversion:1.8.2:*:*:*:*:*:*:*
apachesubversion1.8.3cpe:2.3:a:apache:subversion:1.8.3:*:*:*:*:*:*:*
apachesubversion1.8.4cpe:2.3:a:apache:subversion:1.8.4:*:*:*:*:*:*:*
apachesubversion1.8.5cpe:2.3:a:apache:subversion:1.8.5:*:*:*:*:*:*:*
apachesubversion1.8.6cpe:2.3:a:apache:subversion:1.8.6:*:*:*:*:*:*:*
apachesubversion1.8.7cpe:2.3:a:apache:subversion:1.8.7:*:*:*:*:*:*:*
apachesubversion1.8.8cpe:2.3:a:apache:subversion:1.8.8:*:*:*:*:*:*:*
apachesubversion1.8.9cpe:2.3:a:apache:subversion:1.8.9:*:*:*:*:*:*:*
Rows per page:
1-10 of 141

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

AI Score

7.3

Confidence

High

EPSS

0.001

Percentile

46.5%